Adaptive Machine Learning Model Protection via Secure Enclaves
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face challenges in protecting data privacy and intellectual property of computer programs, particularly when these programs are shared between distinct entities such as enterprises and corporations, especially in the context of Software as a Medical Device (SaMD) where multiple parties are involved.
Innovation Solution
The implementation of secure enclaves (SEs) and heuristic set manipulation methods within secure data pipelines ensures that machine learning programs are protected from unauthorized access, copying, or duplication. This involves encrypting data and programs within SEs, allowing only authenticated users to add remarks to retraining datasets, and using de-identifying algorithms to maintain data privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If machine learning programs are shared between distinct entities for SaMD ecosystem, then adaptability and learning capabilities are improved, but data privacy and intellectual property protection deteriorate
Solution Approach 1:
The patent segments the machine learning program into multiple components: encrypted model weights, separate training data, and distributed computation tasks across multiple parties. This segmentation allows each party to contribute to learning without exposing their complete data or model, thus maintaining privacy while enabling adaptability.
Solution Approach 2:
The patent introduces secure multi-party computation protocols and trusted execution environments as intermediaries that facilitate collaborative learning. These intermediaries enable parties to jointly train models without directly sharing sensitive data, acting as mediators that preserve privacy while enabling adaptability.
2Object-affected harmful factors
If machine learning programs are locked with respect to training data, then intellectual property protection is improved, but adaptability to real world data deteriorates
Solution Approach 1:
The patent implements dynamic model updating mechanisms where the locked model can be periodically retrained with new real-world data through secure protocols. The model transitions from a static locked state to a dynamically updated state, maintaining IP protection during transitions while enabling adaptability through controlled retraining cycles.
Solution Approach 2:
The patent employs preliminary actions by pre-encrypting model weights and pre-establishing secure computation protocols before deployment. This preliminary preparation allows the model to maintain locked status while being pre-configured for future adaptive retraining, balancing IP protection with adaptability readiness.
3Object-affected harmful factors
If secure enclaves are used to encrypt data and programs, then data privacy protection is improved, but device complexity increases
Solution Approach 1:
The patent extracts the complex security operations into separate secure enclaves that are isolated from the main system. This extraction concentrates complexity in dedicated security modules while keeping the primary system simple, allowing strong encryption and privacy protection without overwhelming the overall device complexity.
Solution Approach 2:
The patent designs secure enclaves with multi-functional capabilities that can handle various cryptographic operations, data encryption, and model protection tasks within a single unified security module. This universality reduces overall system complexity by consolidating multiple security functions into one component rather than requiring separate mechanisms for each function.
Data Source
AI summary
Techniques for adaptively improving the performance of a locked machine learning program have been disclosed. In one particular embodiment, the techniques may be realized as a method for enabling a first party to provide a trained machine learning model to a second party, the method comprising receiving the trained machine learning model from the first party, the trained machine learning model being associated with one or more policies defining permissible operations; and constraining the second party to operate the trained machine learning model in a manner that is consistent with said one or more policies.


